Skip to main content

Command Palette

Search for a command to run...

Microservice Banking

Published
•3 min read•View as Markdown
                         ┌───────────────────────────────────────────┐
                         │                 Internet                  │
                         └───────────────▲───────────────────────────┘
                                         │  (HTTPS/HTTP)
                                         │
                               [ AWS NLB on EKS / LB on Minikube ]
                                         │
                              ┌──────────┴──────────┐
                              │  Envoy Gateway (DP) │  ← Gateway API (Gateway/HTTPRoute)
                              └──────────┬──────────┘
                                         │
                    ┌────────────────────┼─────────────────────┐
                    │                    │                     │
                    │ (ext_authz check)  │ (routes to backend) │
                    ▼                    ▼                     ▼
            ┌────────────────┐   ┌─────────────────┐    ┌─────────────────┐
            │  AuthZ Service │   │  orders-service │    │ inventory-service│
            │ (Spring Boot)  │   │  (Spring Boot)  │    │   (Spring Boot)  │
            │ /authz/check   │   │  ClusterIP Svc  │    │   ClusterIP Svc  │
            └───────┬────────┘   └────────┬────────┘    └────────┬────────┘
                    │                     │                        │
                    │                     │                        │
                    │          (east–west calls via K8s Service DNS) 
                    │                     │                        │
                    │        lb://orders-service         lb://inventory-service
                    │                     │                        │
                    │            ┌────────▼────────┐     ┌─────────▼───────┐
                    │            │ Spring Cloud    │     │ Spring Cloud     │
                    │            │ K8s Discovery   │     │ K8s Discovery    │
                    │            │ + LoadBalancer  │     │ + LoadBalancer   │
                    │            └────────┬────────┘     └─────────┬────────┘
                    │                     │                        │
                    │           (K8s API: Services/Endpoints)      │
                    │                     │                        │
            ┌───────▼────────────────────────────────────────────────────────┐
            │                Kubernetes Control Plane (API Server)            │
            │        - Service registry (Services/Endpoints)                 │
            │        - ConfigMaps/Secrets (app config & creds)               │
            └────────────────────────────────────────────────────────────────┘


Observability & Platform Add-ons (same in Minikube/EKS)
──────────────────────────────────────────────────────────────────────────────────
   ┌────────────────┐     ┌──────────────────────┐      ┌─────────────────────┐
   │ Prometheus     │ ←── │ Spring Actuator/Mtrx │  ─→  │ Grafana Dashboards  │
   └────────────────┘     └──────────────────────┘      └─────────────────────┘
           ▲
           │ OTLP (traces/metrics/logs)
   ┌──────────────────────────┐
   │ OpenTelemetry Collector  │  ← Envoy & Spring apps export OTLP
   └──────────────────────────┘

Security Flow (simplified)
──────────────────────────────────────────────────────────────────────────────────
1) Client → Envoy Gateway (JWT in Authorization header)
2) Envoy validates JWT (issuer/JWKS)  [optional during Minikube bring-up]
3) Envoy → AuthZ Service: POST /authz/check (method, path, claims)  → 200/401/403
4) If allowed → Envoy forwards to target backend Service (orders-service, etc.)
5) Services also run Spring Security (resource server) for defense-in-depth


Namespaces (example)
──────────────────────────────────────────────────────────────────────────────────
- platform: Envoy Gateway + Gateway/HTTPRoute (+ TLS secret/cert)
- security: AuthZ Service (your Spring “security repo”)
- apps:     Business services (orders, inventory, …)
- observability: Prometheus, Grafana, OTEL Collector, Loki/ELK (optional)


Minikube → EKS migration notes
──────────────────────────────────────────────────────────────────────────────────
- Replace Minikube LB with AWS NLB via Service annotations (no app changes)
- Add cert-manager/ACM for real TLS certs and switch Gateway listener to HTTPS:443
- Install AWS Load Balancer Controller (provisions the NLB from your Service)
- Keep the same Gateway/HTTPRoute/SecurityPolicy manifests

Loadbalance

awesome — here are two tiny ASCII diagrams showing who load-balances where.

1) North–South (internet → cluster): Envoy does the LB

Client
  │  HTTPS
  ▼
[ Envoy Gateway ]  ← Gateway API (Gateway/HTTPRoute), JWT, ext_authz
  │        │
  │  (LB: picks a pod behind the K8s Service)
  │        ▼
  │   [orders-service  Service (ClusterIP)]
  │        ├────► pod A (orders-abc)
  │        └────► pod B (orders-def)
  │                 ^ round-robin / least-requests (Envoy)
  ▼
Response
  • Envoy balances across pods for the target Service.

  • Policy like round-robin / least-requests is configured on Envoy (via its CRDs).


2) East–West (service → service): Spring does the LB

orders-service (Spring Boot)
  │  calls lb://inventory-service
  │
  │  (Spring Cloud Kubernetes DiscoveryClient)
  │  → queries K8s API for Endpoints of "inventory-service"
  │
  │  (Spring Cloud LoadBalancer)
  │  → picks a pod (client-side LB)
  │
  ├────► pod A (inventory-xyz)
  └────► pod B (inventory-pqr)
        ^ round-robin by default (Spring)
  • Inside the cluster, Spring Cloud LoadBalancer picks the pod (client-side).

  • No Envoy needed for these internal calls (unless you later add a mesh).


Quick mental map

  • External traffic: Envoy = reverse proxy + auth + server-side LB.

  • Internal service calls: Spring Cloud DiscoveryClient + LoadBalancer = client-side LB.

Want me to add a third variant showing both at once (client hits Envoy → orders → inventory), with timeouts/retries labeled?